Export limit exceeded: 90035 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (90035 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2018-14924 | 1 Matera | 1 Banco | 2024-11-21 | N/A |
| Matera Banco 1.0.0 is vulnerable to multiple stored XSS, as demonstrated by the sca/privilegio/consultarUsuario.jsf "Nome Completo" (aka user fullname) field. | ||||
| CVE-2018-14922 | 1 Monstra | 1 Monstra | 2024-11-21 | N/A |
| Multiple cross-site scripting (XSS) vulnerabilities in Monstra CMS 3.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) first name or (2) last name field in the edit profile page. | ||||
| CVE-2018-14919 | 1 Loytec | 2 Lgate-902, Lgate-902 Firmware | 2024-11-21 | N/A |
| LOYTEC LGATE-902 6.3.2 devices allow XSS. | ||||
| CVE-2018-14916 | 1 Loytec | 2 Lgate-902, Lgate-902 Firmware | 2024-11-21 | N/A |
| LOYTEC LGATE-902 6.3.2 devices allow Arbitrary file deletion. | ||||
| CVE-2018-14906 | 1 3cx | 1 3cx Web Server | 2024-11-21 | N/A |
| The Web server in 3CX version 15.5.8801.3 is vulnerable to Reflected XSS on all stack traces' propertyPath parameters. | ||||
| CVE-2018-14905 | 1 3cx | 1 3cx Web Server | 2024-11-21 | N/A |
| The Web server in 3CX version 15.5.8801.3 is vulnerable to Reflected XSS on the api/CallLog TimeZoneName parameter. | ||||
| CVE-2018-14904 | 1 Samsung | 1 Syncthru Web Service | 2024-11-21 | N/A |
| Samsung Syncthru Web Service V4.05.61 is vulnerable to Multiple unauthenticated XSS attacks on several parameters, as demonstrated by ruiFw_pid. | ||||
| CVE-2018-14901 | 1 Epson | 1 Iprint | 2024-11-21 | N/A |
| The EPSON iPrint application 6.6.3 for Android contains hard-coded API and Secret keys for the Dropbox, Box, Evernote and OneDrive services. | ||||
| CVE-2018-14899 | 1 Epson | 2 Wf-2750, Wf-2750 Firmware | 2024-11-21 | N/A |
| On the EPSON WF-2750 printer with firmware JP02I2, the Web interface AirPrint Setup page is vulnerable to HTML Injection that can redirect users to malicious sites. | ||||
| CVE-2018-14893 | 1 Zyxel | 2 Nsa325 V2, Nsa325 V2 Firmware | 2024-11-21 | N/A |
| A system command injection vulnerability in zyshclient in ZyXEL NSA325 V2 version 4.81 allows attackers to execute system commands via the web application API. | ||||
| CVE-2018-14890 | 1 Vectra | 1 Cognito | 2024-11-21 | N/A |
| Vectra Networks Cognito Brain and Sensor before 4.2 contains a cross-site scripting (XSS) vulnerability in the Web Management Console. | ||||
| CVE-2018-14888 | 1 Thank You\/like Project | 1 Thank You\/like | 2024-11-21 | N/A |
| inc/plugins/thankyoulike.php in the Eldenroot Thank You/Like plugin before 3.1.0 for MyBB allows XSS via a post or thread subject. | ||||
| CVE-2018-14886 | 1 Odoo | 1 Odoo | 2024-11-21 | N/A |
| The module-description renderer in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier does not disable RST's local file inclusion, which allows privileged authenticated users to read local files via a crafted module description. | ||||
| CVE-2018-14877 | 1 Weaselcms Project | 1 Weaselcms | 2024-11-21 | N/A |
| An issue was discovered in WeaselCMS v0.3.5. XSS exists via Site Language, Site Title, Site Description, and Site Keywords on the SETTINGS page. | ||||
| CVE-2018-14875 | 1 Polarisft | 1 Intellect Core Banking | 2024-11-21 | N/A |
| An issue was discovered in the Core and Portal modules in Polaris FT Intellect Core Banking 9.7.1. Reflected XSS exists with an authenticated session via the Customerid, formName, FrameId, or MODE parameter. | ||||
| CVE-2018-14873 | 1 Rincewind Project | 1 Rincewind | 2024-11-21 | N/A |
| An issue was discovered in Rincewind 0.1. There is a cross-site scripting (XSS) vulnerability involving a p=account request to index.php and another file named commonPages.php. | ||||
| CVE-2018-14869 | 1 Php Template Store Script Project | 1 Php Template Store Script | 2024-11-21 | N/A |
| PHP Template Store Script 3.0.6 allows XSS via the Address line 1, Address Line 2, Bank name, or A/C Holder name field in a profile. | ||||
| CVE-2018-14866 | 1 Odoo | 1 Odoo | 2024-11-21 | N/A |
| Incorrect access control in the TransientModel framework in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated attackers to access data in transient records that they do not own by making an RPC call before garbage collection occurs. | ||||
| CVE-2018-14862 | 1 Odoo | 1 Odoo | 2024-11-21 | N/A |
| Incorrect access control in the mail templating system in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows authenticated internal users to delete arbitrary menuitems via a crafted RPC request. | ||||
| CVE-2018-14861 | 1 Odoo | 1 Odoo | 2024-11-21 | N/A |
| Improper data access control in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows authenticated users to perform a CSV export of the secure hashed passwords of other users. | ||||